Self-hosted runner

Bivouac, inside your network.

The same audit-logged agent runner that ships managed, deployed as a single binary on a host you control. Built for regulated repos, air-gapped environments, and data-residency requirements where SaaS isn’t on the table. Join the waitlist and we’ll work with the first cohort on the install posture that matches your perimeter.

What changes when the runner is yours

Air-gapped by design

Single binary, no outbound network calls except the LLM egress proxy you operate. Policy packs loaded from a local file.

Regulated repos, accepted

For buyers under FINMA, BaFin, APRA / CPS 234, DORA, and similar — the same audit-logged chain of patch decisions, reproduced inside your perimeter.

Data residency, owned

Tenant rows pinned to the region you choose. Backups encrypted at rest, pulled only by your team. No third-country replication.

Same evidence, same model

The minutes-not-weeks MTTR and the audit-logged chain of patch decisions ship identical to managed — the runner just lives with you.

Targets we’re shipping first

The runner reads the host platform through the same scoped credentials a CI job would use — the difference is where the policy pack and the audit log live.

  • GitHub Enterprise

    Self-hosted runners, GitHub Apps API.

  • GitLab Self-Managed

    CE / EE on-prem, instance-level tokens.

  • Bitbucket Data Center

    Clustered DC, smart-mirror / DC licenses.

First-cohort waitlist

Be in the first cohort.

We’re piloting the self-hosted runner with a small group of buyers who need it today. Drop your work email and we’ll reach out within a week with the install posture (Docker / Helm) and a private channel for the first deployment.

We use this only for the self-hosted rollout. No newsletter, no third-party sharing.

Buyer questions

What compliance teams ask before we install